<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Crypto Map - Address Matching question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254632#M834828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also post he output for these commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show crypto isakmp sa&lt;/P&gt;&lt;P&gt;show crypto ipsec sa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Jun 2009 14:24:53 GMT</pubDate>
    <dc:creator>srikantganesh</dc:creator>
    <dc:date>2009-06-11T14:24:53Z</dc:date>
    <item>
      <title>Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254625#M834818</link>
      <description>&lt;P&gt;Hi, I have three policies (see below)which make up a crypto map policy on a security device. &lt;/P&gt;&lt;P&gt;How does policy 10 match traffic if there is no "match address" statement? This is the peer I wish to edit but don't know how it is matching? Is there a default addressing match assumed?&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 10 set peer 100.200.300.1&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 10 set transform-set MY_TS_SET&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 20 match address POLICY_ACL1&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 20 set peer 100.200.300.50&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 20 set transform-set MY_TS_SET&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 30 match address POLICY_ACL2&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 30 set peer 100.200.300.100&lt;/P&gt;&lt;P&gt;crypto map MYCRYPTO_MAP 30 set transform-set MY_TS_SET2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gerry&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254625#M834818</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2019-03-11T15:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254626#M834821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A match address will be needed to specify interesting traffic.&lt;/P&gt;&lt;P&gt;Check if the VPN is even up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show crypto isakmp sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to test the VPN if it is not up?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 13:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254626#M834821</guid>
      <dc:creator>srikantganesh</dc:creator>
      <dc:date>2009-06-11T13:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254627#M834823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how is the other side configured? as a dynamic map?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 13:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254627#M834823</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-06-11T13:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254628#M834824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Srikant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN is deinately up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gerard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254628#M834824</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2009-06-11T14:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254629#M834825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;under tunnel group for this vpn or the group policy is there any specific acl settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the tunnel group, group policy and crypto config for this vpn?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254629#M834825</guid>
      <dc:creator>srikantganesh</dc:creator>
      <dc:date>2009-06-11T14:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254630#M834826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other end is checkpoint firewall with both subnets A&amp;lt;--&amp;gt;B allowed in both directions to form the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gerry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254630#M834826</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2009-06-11T14:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254631#M834827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Srikant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No ACL settings...that is why I was wondering how the traffic is being matched? Is there a default setting?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel config below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group 100.200.300.1 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 100.200.300.1 general-attributes&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt;tunnel-group 100.200.300.1 ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt; peer-id-validate req&lt;/P&gt;&lt;P&gt; no chain&lt;/P&gt;&lt;P&gt; no trust-point&lt;/P&gt;&lt;P&gt; isakmp keepalive threshold 10 retry 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gerard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254631#M834827</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2009-06-11T14:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254632#M834828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also post he output for these commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show crypto isakmp sa&lt;/P&gt;&lt;P&gt;show crypto ipsec sa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254632#M834828</guid>
      <dc:creator>srikantganesh</dc:creator>
      <dc:date>2009-06-11T14:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254633#M834829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show crypto isakmp sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4   IKE Peer: 100.200.300.1 &lt;/P&gt;&lt;P&gt;    Type    : L2L             Role    : responder &lt;/P&gt;&lt;P&gt;    Rekey   : no              State   : MM_ACTIVE &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW# show vpn-sessiondb detail l2l filter ipaddress 100.200.300.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session Type: LAN-to-LAN Detailed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connection   : 100.200.300.1&lt;/P&gt;&lt;P&gt;Index        : 1                      IP Addr      : 100.200.300.1&lt;/P&gt;&lt;P&gt;Protocol     : IPSecLAN2LAN           Encryption   : 3DES&lt;/P&gt;&lt;P&gt;Hashing      : SHA1                   &lt;/P&gt;&lt;P&gt;Bytes Tx     : 996874716              Bytes Rx     : 622313494&lt;/P&gt;&lt;P&gt;Login Time   : 10:40:07 UTC Thu Jun 11 2009&lt;/P&gt;&lt;P&gt;Duration     : 4h:33m:13s&lt;/P&gt;&lt;P&gt;Filter Name  : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE Sessions: 1&lt;/P&gt;&lt;P&gt;IPSec Sessions: 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE:&lt;/P&gt;&lt;P&gt;  Session ID   : 1&lt;/P&gt;&lt;P&gt;  UDP Src Port : 500                    UDP Dst Port : 500&lt;/P&gt;&lt;P&gt;  IKE Neg Mode : Main                   Auth Mode    : preSharedKeys&lt;/P&gt;&lt;P&gt;  Encryption   : AES256                 Hashing      : SHA1&lt;/P&gt;&lt;P&gt;  Rekey Int (T): 86400 Seconds          Rekey Left(T): 70008 Seconds&lt;/P&gt;&lt;P&gt;  D/H Group    : 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254633#M834829</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2009-06-11T14:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254634#M834832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try show ipsec sa peer 100.200.300.1&lt;/P&gt;&lt;P&gt;This should include the traffic it is encrypting/decrypting for this VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254634#M834832</guid>
      <dc:creator>srikantganesh</dc:creator>
      <dc:date>2009-06-11T14:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Map - Address Matching question</title>
      <link>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254635#M834833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Srikant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There appears to be a local and remote subnet listed for source and desintation but I cannot find where this is defined?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the point of my posting as I cannot locate where it is reading this information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gerard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jun 2009 14:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-map-address-matching-question/m-p/1254635#M834833</guid>
      <dc:creator>crazyhorse29</dc:creator>
      <dc:date>2009-06-11T14:37:32Z</dc:date>
    </item>
  </channel>
</rss>

